WordPress Plugin Import all XML, CSV & TXT into WordPress is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information (usernames, hashed passwords and email addresses) that may help in launching further attacks. WordPress Plugin Import all XML, CSV & TXT into WordPress version 3.6.74 is vulnerable; prior versions are also affected.
Update to plugin version 3.6.75 or latest
WordPress Plugin AllWebMenus WordPress Menu 'actions.php' Arbitrary File Upload (1.1.8)
WordPress Plugin Better Search Cross-Site Request Forgery (2.5.2)
WordPress Plugin Contact Form by BestWebSoft Email Header Injection (3.83)
WordPress Plugin Redirect 404 to parent Cross-Site Scripting (1.3.0)
WordPress Plugin Happy Addons for Elementor Cross-Site Scripting (2.23.0)